Has Suitable Airlock 2FA Device
Condition that is fulfilled if the user has at least one Airlock 2FA device that is active and capable of at least one of the allowed factors.
The allowed authentication factors are determined as the common factors between:
- The factors configured here. These factors are the same for all users.
- The factors that are enabled for the user in the Futurae administration service.
If bypass mode is not enabled in the Airlock 2FA settings, this condition will not be satisfied for users for which the Futurae bypass mode is enabled. If bypass mode is enabled in the Airlock 2FA settings, this condition will be satisfied for all users for which the Futurae bypass mode is enabled.
factors) List of all enabled factors. The condition is fulfilled, if the user has at least one device that is capable of at least one of the factors listed here.
Available factors:
- One-Touch: a push message is sent to the user's mobile app, where it must be approved. This is an online factor.
- Online QR Code: a QR code is displayed in the browser, which has to be scanned by a mobile app and approved there. This is an online factor.
- Passcode: the device (mobile app or hardware token) generates a time-dependent code (OTP) that has to be entered manually. This is an offline factor.
- Offline QR Code: a QR code is displayed which has to be scanned by a mobile app or hardware token. The device displays a code (OTP) that must be entered manually. This is an offline factor.
airlock2faSettings) Settings of Airlock 2FA.
It is recommended to use the same settings everywhere. Otherwise, behaviour of the condition could seem inconsistent.
respectCooldown) Whether to ignore Cooldown information.
If disabled, the step ignores the "Cooldown Period" for new devices configured in the "Airlock 2FA Settings". This is typically used for authentication steps that protect low-risk applications, such as a portal page, which can also be accessed using devices in cooldown.
If no "Cooldown Period" is defined, enabling this property has no effect.
type: Airlock2FAHasDeviceCondition
id: Airlock2FAHasDeviceCondition-xxxxxx
displayName:
comment:
properties:
airlock2faSettings:
factors: [One-Touch, Online QR Code, Passcode, Offline QR Code]
respectCooldown: true